ROPA
GDPR Article 30 Records of Processing (ROPA) Checklist
A ROPA checklist to inventory processing activities, recipients, transfers, and retention for Article 30.
- Estimated time
- 3–8 Weeks
- Audience
- Privacy and Legal Operations Teams
- Last updated
Operational reference for Article 30 records. Controllers and processors have different required fields.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Collect
Phase 2: Complete Fields
Phase 3: Quality
Phase 4: Use
FAQ
Who must keep a ROPA?+–
Controllers and processors, with SME exceptions that are narrow—most growing SaaS should keep one.
Must it be public?+–
No. It must be provided to the authority on request.
Is a ROPA a DPIA?+–
No. ROPA is an inventory. DPIA is a risk analysis for high-risk processing.
Controller vs processor records?+–
Article 30(1) vs 30(2) fields differ. SaaS often needs both.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer